Vulnerabilities (CVE)

Filtered by vendor Symantec Subscribe
Filtered by product Management Center
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-18376 1 Symantec 1 Management Center 2024-02-04 4.3 MEDIUM 5.9 MEDIUM
A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to perform CSRF attacks against MC.
CVE-2019-9697 1 Symantec 1 Management Center 2024-02-04 4.0 MEDIUM 6.5 MEDIUM
An information disclosure vulnerability in the Management Center (MC) REST API 2.0, 2.1, and 2.2 prior to 2.2.2.1 allows a malicious authenticated user to obtain passwords for external backup and CPL policy import servers that they might not otherwise be authorized to access.